isomorphic-git/cors-proxy

isomorphic-git/cors-proxy

Releases19
Frequency6 months 1 day
Last Release
Stars105
Proxy clone and push requests for the browser

CVE History

CVEPublishedCVSS v3CVSS v2
8.6 HIGH5 MEDIUM

The package @isomorphic-git/cors-proxy before 2.7.1 are vulnerable to Server-side Request Forgery (SSRF) due to missing sanitization and validation of the redirection action in middleware.js.